˼¿ÆÐû²¼¶àÖÖ²úÆ·µÄÇå¾²¸üР£¬£¬£¬£¬ £¬£¬ÐÞ¸´´úÂëÖ´ÐÐÎó²î£»£»£»Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA) £¬£¬£¬£¬ £¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û

Ðû²¼Ê±¼ä 2020-07-17

1.˼¿ÆÐû²¼¶àÖÖ²úÆ·µÄÇå¾²¸üР£¬£¬£¬£¬ £¬£¬ÐÞ¸´´úÂëÖ´ÐÐÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


˼¿ÆÐû²¼ÁËÇå¾²¸üР£¬£¬£¬£¬ £¬£¬ÐÞ¸´Ó°Ïì¶à¸ö²úÆ·µÄÎó²î £¬£¬£¬£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉʹÓÃÆäÖеÄijЩÎó²îÀ´¿ØÖÆÊÜÓ°Ïìϵͳ¡£¡£¡£¡£ ¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²î°üÀ¨Ð¡ÐÍÆóÒµ·À»ðǽRV110W Wireless-N VPN¾²Ì¬Ä¬ÈÏÆ¾Ö¤Îó²î£¨CVE-2020-3330£©¡¢Ð¡ÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2020-3323£©¡¢RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-3144£©¡¢RV110WºÍRV215WϵÁзÓÉÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3331£© £¬£¬£¬£¬ £¬£¬ÒÔ¼°Cisco Prime License ManagerÌØÈ¨Éý¼¶Îó²î£¨CVE-2020-3140£©¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products


2.Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA) £¬£¬£¬£¬ £¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ºÚ¿Í×éÖ¯Ghost Squad Hackers¹¥»÷ÁËÅ·ÖÞº½Ìì¾Ö(ESA) £¬£¬£¬£¬ £¬£¬²¢µ¼ÖÂÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£¡£¡£ ¡£¡£Ôڴ˴ι¥»÷ÖÐ £¬£¬£¬£¬ £¬£¬ºÚ¿ÍʹÓÃЧÀÍÆ÷ÖеÄЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î £¬£¬£¬£¬ £¬£¬»ñµÃÁ˶Ôbusiness.esa.intÓòµÄ»á¼ûȨ²¢¶ÔÆä¾ÙÐÐÁËÆÆË𡣡£¡£¡£ ¡£¡£¸Ã×éÖ¯³ÉÔ±s1egeÌåÏÖ £¬£¬£¬£¬ £¬£¬ËûÃÇÊǺڿÍÖ÷ÒåÕß £¬£¬£¬£¬ £¬£¬Í¨³£»£»£»áÒò¼¤½øÖ÷ÒåµÄÔµ¹ÊÔ­ÓÉÌᳫ¹¥»÷ £¬£¬£¬£¬ £¬£¬¶ø´Ë´Î¹¥»÷´¿´âÊdzöÓÚÓéÀÖÄ¿µÄ¡£¡£¡£¡£ ¡£¡£¸Ã×éÖ¯ÔÚ½ü¼¸ÄêÒѾ­ÈëÇÖÁËÐí¶à×éÖ¯ºÍÕþ¸®»ú¹¹ £¬£¬£¬£¬ £¬£¬°üÀ¨ÃÀ¾ü¡¢Å·ÃË¡¢»ªÊ¢¶ÙÌØÇø¡¢ÒÔÉ«Áйú·À¾ü¡¢Ó¡¶ÈÕþ¸®ºÍһЩÖÐÑëÒøÐС£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105918/hacktivism/european-space-agency-esa-site-defacement.html?utm_source=rss&utm_medium=rss&utm_campaign=european-space-agency-esa-site-defacement


3.Å·ÖÞ·ºÆðÐÂÐ͵ÄATMºÚºÐ¹¥»÷ £¬£¬£¬£¬ £¬£¬Õë¶ÔProCash 2050xe ATMÖÕ¶Ë


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ATMÖÆÔìÉÌDiebold NixdorfÖÒÑÔÒøÐÐ £¬£¬£¬£¬ £¬£¬×î½üÔÚÅ·ÖÞ·¢Ã÷ÁËÒ»ÖÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷ £¬£¬£¬£¬ £¬£¬ÕâÊÇÒ»ÖÖÍ·½±£¨Jackpotting£©¹¥»÷ £¬£¬£¬£¬ £¬£¬Ôâµ½¹¥»÷µÄATM »áÏñÖÐÁËÍ·½±µÄÀÏ»¢»úÒ»Ñù £¬£¬£¬£¬ £¬£¬Ò»Ö±Í·ºÆð½ð¡£¡£¡£¡£ ¡£¡£´ËÐÂÐ͹¥»÷½öÕë¶ÔProCash 2050xe ATMÖÕ¶Ë £¬£¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýUSB¶Ë¿ÚÅþÁ¬µ½×°±¸¡£¡£¡£¡£ ¡£¡£ºÚ¿ÍÊ×ÏÈÆÆË𲿷ֽṹÒÔ±ã½øÈë»úеÄÚ²¿ £¬£¬£¬£¬ £¬£¬½ÓÏÂÀ´°ÎµôCMD-V4·ÖÅÉÆ÷ºÍרÓõç×Ó×°±¸Ö®¼äµÄUSBÏß £¬£¬£¬£¬ £¬£¬»òÕßרÓõç×Ó×°±¸ºÍATM PCÖ®¼äµÄÏß £¬£¬£¬£¬ £¬£¬²¢½«ÕâÌõÏßÅþÁ¬µ½¹¥»÷ÕߵĺںР£¬£¬£¬£¬ £¬£¬ÒÔ·¢ËͲ»·¨ÏÂÁî¡£¡£¡£¡£ ¡£¡£ÏÖÔÚ £¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÕýÔÚÊÓ²ìºÚ¿ÍÊÇÔõÑù»ñµÃÕâЩÁã¼þµÄ¡£¡£¡£¡£ ¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/diebold-nixdorf-warns-of-a-new-class-of-atm-black-box-attacks-across-europe/#ftag=RSSbaffb68


4.кóÃÅBazarÓëTrickbotÓÐ¹Ø £¬£¬£¬£¬ £¬£¬Õë¶ÔµÄÄ¿µÄÊÇÃÀ¹úºÍÅ·ÖÞ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Cybereason NocturnusÑо¿Ð¡×é·¢Ã÷ÁËкóÃÅBazarÓëTrickbotÓÐ¹Ø £¬£¬£¬£¬ £¬£¬×Ô½ñÄê4ÔÂÒÔÀ´ £¬£¬£¬£¬ £¬£¬¸ÃºóÃÅÒѱ»ÓÃÓÚ¹¥»÷ÃÀ¹úºÍÅ·ÖÞµÄÄ¿µÄ £¬£¬£¬£¬ £¬£¬ÌØÊâÊÇÒ½ÁƱ£½¡¡¢IT¡¢ÖÆÔì¡¢ÎïÁ÷ºÍÂÃÓÎÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£ ¡£¡£ÔÚ¾àÀëÁ½¸öÔÂºó £¬£¬£¬£¬ £¬£¬6Ô·ºÆðÁ˸úóÃŵÄÐÂÑù±¾ £¬£¬£¬£¬ £¬£¬ÒÔ¼°Ë¢ÐµĴúÂëºÍÐÞ¸´³ÌÐò¡£¡£¡£¡£ ¡£¡£¸ÃºóÃÅÓëTrickbot¼ÓÔØ³ÌÐò¾ßÓÐÏàËÆµÄ´úÂë £¬£¬£¬£¬ £¬£¬°üÀ¨ÏàͬµÄWinAPI¡¢×Ô½ç˵RC4ʵÏֺͷ±ËöµÄ»ìÏý¡£¡£¡£¡£ ¡£¡£¼ÓÃܵÄBazar»áÖ±½Ó¼ÓÔØµ½ÄÚ´æÖÐ £¬£¬£¬£¬ £¬£¬ÒÔÌÓ±Üɱ¶¾Èí¼þµÄ¼ì²â¡£¡£¡£¡£ ¡£¡£ÏÖÔÚÒѱ»¼ì²âµ½µÄBazarÓÐÈý¸ö°æ±¾ £¬£¬£¬£¬ £¬£¬´¦ÓÚ²î±ðµÄ¿ª·¢½×¶Î £¬£¬£¬£¬ £¬£¬°üÀ¨ÍøÂçºÍÇÔȡϵͳÊý¾Ý¡¢ÓëÖ¸»Ó¿ØÖÆ(C2)½¨ÉèÅþÁ¬ £¬£¬£¬£¬ £¬£¬ÒÔ¼°Ö´ÐжàÖÖ¹¦Ð§¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-bazar-backdoor-linked-to-trickbot-banking-trojan-campaigns/


5.Ó¡Äṫ˾BhinnekaÔâµ½¹¥»÷ £¬£¬£¬£¬ £¬£¬Ð¹Â¶Áè¼Ý100Íò¸öÕÊ»§ÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Hackread.com·¢Ã÷ £¬£¬£¬£¬ £¬£¬Ó¡ÄáÔÚÏßÉ̳ÇBhinnekaÔâµ½¹¥»÷й¶Áè¼Ý100Íò¸öÕÊ»§ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¾ÝϤ £¬£¬£¬£¬ £¬£¬´Ë´ÎÊÂÎñй¶ÁËÁ½¸öSQLÎļþ £¬£¬£¬£¬ £¬£¬×ܹ²°üÀ¨Ô¼Äª1262300¸öÕÊ»§µÄ¼Í¼ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£Ð¹Â¶ÐÅÏ¢°üÀ¨Î¨Ò»µÄID¡¢È«Ãû¡¢µç×ÓÓʼþµØµã¡¢ÐÔ±ð¡¢ÁªÂçµç»°¡¢ÃÜÂë¡¢ÏêϸµØµã¡¢³öÉúÈÕÆÚ¡¢É罻ýÌåID¡¢ÈÕÖ¾ÏêϸÐÅÏ¢¡¢Óû§Éí·Ý£¨ÊÇÖÎÀíÔ±ÕÕÍùÊÂÇéÖ°Ô±£© £¬£¬£¬£¬ £¬£¬»¹¿ÉÄܰüÀ¨Ô±¹¤ÏêϸÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¾ÝϤ £¬£¬£¬£¬ £¬£¬´Ë´Î¹¥»÷±¬·¢ÓÚ½ñÄê1ÔÂ27ÈÕ £¬£¬£¬£¬ £¬£¬ºÚ¿Í×î³õÊÔͼͨ¹ýÀÕË÷Êê½ð»ò³öÊÛÒÔ»ñÈ¡ÀûÒæ £¬£¬£¬£¬ £¬£¬µ«²»Öª³öÓÚºÎÖÖÔµ¹ÊÔ­ÓÉ £¬£¬£¬£¬ £¬£¬ºÚ¿Í×îºó½«ÆäÃâ·Ñ¹ûÕæÔÚÁËÍøÂçÉÏ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/indonesia-bhinneka-database-dumped-1-million-accounts/


6.Kaspersky±¨¸æ £¬£¬£¬£¬ £¬£¬4¿î°ÍÎ÷ÒøÐÐľÂíÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Kaspersky±¨¸æ £¬£¬£¬£¬ £¬£¬ÏÈÈÝÁËÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄ4¿î°ÍÎ÷ÒøÐÐľÂí¡£¡£¡£¡£ ¡£¡£ÕâЩľÂí°üÀ¨Guildma¡¢Javali¡¢MelcozºÍGrandoreiro £¬£¬£¬£¬ £¬£¬ËüÃÇÒѾ­½ø»¯³öÁ˳䵱ºóÃŵÄÄÜÁ¦ £¬£¬£¬£¬ £¬£¬²¢½ÓÄÉÁËÖÖÖÖ»ìÏýÊÖÒÕÀ´Òþ²ØÆä¶ñÒâ»î¶¯ £¬£¬£¬£¬ £¬£¬Ê¹Æä²»±»Çå¾²Èí¼þ·¢Ã÷¡£¡£¡£¡£ ¡£¡£KasperskyÑо¿Ö°Ô±½«ËüÃÇͳ³ÆÎªTetrade £¬£¬£¬£¬ £¬£¬²¢Ö¸³öÆä¿ÉÄÜÒѾöÒ齫¹¥»÷À©Õ¹ÖÁÍâÑ󡣡£¡£¡£ ¡£¡£GuildmaºÍJavali¾ù½ÓÄɶà½×¶Î¶ñÒâÈí¼þ°²ÅÅÀú³Ì £¬£¬£¬£¬ £¬£¬Ê¹ÓÃÍøÂç´¹ÂÚµç×ÓÓʼþ×÷Ϊ·Ö·¢³õʼÓÐÓÃÔØºÉµÄ»úÖÆ¡£¡£¡£¡£ ¡£¡£MelcozÊÇ¿ªÔ´RATÔ¶³Ì»á¼ûPCµÄÒ»ÖÖ±äÌå £¬£¬£¬£¬ £¬£¬ÇÔÈ¡ÃÜÂëºÍ±ÈÌØ±ÒÇ®°ü¡£¡£¡£¡£ ¡£¡£Grandoreiro»áʹÓÃÓòÌìÉúËã·¨£¨DGA£©Òþ²Ø¹¥»÷Àú³ÌÖÐʹÓõÄC2µØµã £¬£¬£¬£¬ £¬£¬²¢½«ÆäÍйÜÔÚGoogleÕ¾µãÒ³ÃæÉÏ £¬£¬£¬£¬ £¬£¬Í¨¹ýÊÜѬȾµÄÍøÕ¾ºÍGoogle Ads £¬£¬£¬£¬ £¬£¬»òÓã²æÊ½ÍøÂç´¹ÂÚ¾ÙÐзַ¢¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/the-tetrade-brazilian-banking-malware/97779/